BRP: Query-Efficient Block Revert Patch for Decision-Based Black-Box Adversarial Attack
Zenghui Yang, Xingquan Zuo, Gang Chen, Hai Huang, Tianle Zhang
摘要
Adversarial patches pose a serious threat to deep neural networks, as small localized perturbations can decisively control model predictions. In real-world deployments, the decision-based black-box setting is the most realistic and challenging threat model, where attackers observe only the predicted labels. Designing adversarial patch attacks under this setting is of substantial real-world significance for rigorously testing model robustness under realistic black-box conditions. However, adversarial patch attacks in the decision-based setting remain largely underexplored. Existing methods often suffer from low query efficiency and require large patch areas, which significantly limit their practical applicability. We propose Block Revert Patch (BRP), a novel reverse construction method for query-efficient adversarial patch generation. Instead of adding perturbations, BRP formulates patch generation as a pixel-block reversion problem and employs a two-stage process to progressively refine the patch. Specifically, the single-block revert test stage uses a sliding window to temporarily revert individual blocks and collect those whose reversion maintains the adversarial effect. The global revert optimization stage then searches for an optimal combination of pixel-blocks from this set, further reducing the patch size. By iteratively alternating between these two stages, BRP progressively refines the patch in a coarse-to-fine manner. Experiments show that BRP significantly reduces patch size and query cost compared to state-of-the-art decision-based attacks, offering a strong and practical approach for evaluating model vulnerability in adversarial settings.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- BadPart: Unified Black-box Adversarial Patch Attacks against Pixel-wise Regression TasksZhiyuan Cheng, Zhaoyi Liu, Tengda Guo, Shiwei Feng 等ICML 2024 · 被引用 10 次
- A Geometry-Inspired Decision-Based AttackYujia Liu, Seyed-Mohsen Moosavi-Dezfooli, Pascal FrossardICCV 2019 · 被引用 55 次
- AutoDA: Automated Decision-based Iterative Adversarial AttacksQi-An Fu, Yinpeng Dong, Hang Su, Jun Zhu 等USENIX Security 2022
- BounceAttack: A Query-Efficient Decision-based Adversarial Attack by Bouncing into the WildJie Wan, Jianhao Fu, Lijin Wang, Ziqi YangS&P 2024 · 被引用 13 次
- Decision-based Black-box Attack Against Vision Transformers via Patch-wise Adversarial RemovalYucheng Shi, Yahong Han, Yu-an Tan, Xiaohui KuangNeurIPS 2022 · 被引用 43 次
